Publication | Closed Access
Configurable string matching hardware for speeding up intrusion detection
115
Citations
11
References
2005
Year
EngineeringHigh Performance Computer NetworkInformation SecurityComputer ArchitectureHardware SecurityString-searching AlgorithmString ProcessingParallel ComputingSoftware IdssAttack SignaturesIntrusion Detection SystemIntrusion ToleranceComputer EngineeringHash FunctionComputer ScienceMonitor Network TrafficData SecurityCryptographyIntrusion Detection
Signature-based Intrusion Detection Systems (IDSs) monitor network traffic for security threats by scanning packet payloads for attack signatures. IDSs have to run at wire speed and need to be configurable to protect against emerging attacks. In this paper we consider the problem of string matching which is the most computationally intensive task in IDS. A configurable string matching accelerator is developed with the focus on increasing throughput while maintaining the configurability provided by the software IDSs. Our preliminary results suggest that the hardware accelerator offers an overall system performance of up to 14Gbps.
| Year | Citations | |
|---|---|---|
Page 1
Page 1